CVE-2026-41200 | NUWCDIVNPT stig-manager up to 1.6.7 src/init.js error/error_description cross site scripting (GHSA-wg33-j3rv-jq72 / EUVD-2026-25158)
A vulnerability labeled as problematic has been found in NUWCDIVNPT stig-manager up to 1.6.7. Affected by this issue is some unknown functionality of the file src/init.js. Such manipulation of the argument error/error_description leads to cross site scripting.
This vulnerability is documented as CVE-2026-41200. The attack can be executed remotely. There is not any exploit available.
The affected component should be upgraded.